Volo Protocol said a security incident on the Sui blockchain led to losses of $3.5 million after a vault admin private key was compromised. The project said three vaults were affected in the April 21, 2026 attack, all vaults have now been frozen, and a full post-mortem will be published after the investigation is finished.
Three vaults drained of WBTC, XAUm, and USDC
The exploited vaults held wrapped bitcoin (WBTC), Matrixdock’s tokenized gold asset XAUm, and USDC. Independent breakdowns put the losses at about $2.1 million in WBTC, $0.9 million in XAUm, and $0.5 million in USDC. Volo said the remaining vaults were not affected and showed no shared vulnerability. Those unaffected vaults accounted for roughly $28 million in total value locked.
The team said it detected the breach quickly, froze every vault, notified the Sui Foundation, and began working with onchain investigators and ecosystem partners to trace and recover the stolen assets. In a post on X, Volo said it is prepared to absorb the full loss rather than pass the cost to depositors. The project added that it is still in damage-control mode and will release a remediation plan together with the post-mortem.
$500,000 frozen early, 19.6 WBTC bridge move blocked
According to Volo, about $500,000 of the stolen assets was frozen within 30 minutes of the first public announcement through coordination with ecosystem partners. On April 22, the team said it also intercepted the attacker’s attempt to bridge out 19.6 WBTC, worth about $2.1 million at the time. Volo said those funds are no longer under the attacker’s control.
Preliminary onchain analysis identified the attacker address as 0xe76970bbf9b038974f6086009799772db5190f249ce7d065a581b1ac0adaef75. Researchers said the address used functions including withdraw_with_account_cap_v2 to drain the vaults. GoPlus Security, ExVul Security, and Bitslab each pointed to a compromised high-privilege operator key as the root cause, rather than a flaw in Volo’s core smart contracts.
Audits were in place, but key management failed
GoPlus said the compromise was linked to social engineering and related fraud methods targeting the vault admin account. That places the incident in the category of key-management failure instead of a protocol-level code bug. Before the exploit, Volo had completed audits with Ottersec, Movebit, and Hacken, and it also had an active bug bounty program.
All vaults remain frozen. Volo and its partners are working to return the blocked WBTC to the protocol, and a detailed remediation plan is expected in the upcoming post-mortem. Depositors in unaffected vaults have not reported losses so far, and the team directed users to its official X account, @volo_sui, for updates.
The incident came during a month of heavy DeFi losses in April 2026. The report noted that cumulative losses across protocols had surpassed $600 million by some estimates. In Volo’s case, the breach added to a pattern security researchers have been tracking across multiple blockchain ecosystems: access-control and key-management failures continuing to cause major losses even when protocols have already passed formal audits.

